Critical severity9.8NVD Advisory· Published Jan 2, 2023· Updated Jun 17, 2026
CVE-2022-4357
CVE-2022-4357
Description
The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:letsrecover_project:letsrecover:*:*:*:*:*:wordpress:*:*Range: <=1.1.0
- WordPress/LetsRecoverdescription
- Range: <1.2.0
Patches
Vulnerability mechanics
References
3- bulletin.iese.de/post/letsrecover-woocommerce-abandoned-cart_1-1-0_1nvdBroken LinkThird Party Advisory
- wpscan.com/vulnerability/4d1c0886-11f7-494f-b175-691253f46626nvdThird Party Advisory
- wpscan.com/vulnerability/4d1c0886-11f7-494f-b175-691253f46626/nvd
News mentions
0No linked articles in our index yet.